SupportsQualitative · 2023
Pilavakis et al. — Proceedings 2023 Symposium on Usable Security (USEC 2023)
People who report suspected phishing typically describe evidence they noticed, possible impacts, what they did or did not do, and questions they have. Some build clear arguments for why the email is phishing and why the organization should act.
SupportsField experiment · 2020
Reinheimer et al. — Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020)
After an awareness program, employees identified phishing and legitimate emails significantly better right away and at four months, but the gain was gone by six months. Reminders based on videos and interactive examples worked best and lasted at least another six months.
SupportsConceptual · 2019
Zimmermann & Renaud — International Journal of Human-Computer Studies, 131, 169-187
A problematization analysis finds government, industry and hacker discourse treats humans as the problem, with controls designed to constrain them. The authors propose 'Cybersecurity, Differently', which assumes people are well-intentioned and builds on what contributes to positive outcomes and resilience.
SupportsMixed methods · 2018
Vance et al. — MIS Quarterly, 42(2), 355-380
Attention to repeated security warnings declined measurably in the brain across a workweek, partially recovering between days. In the field, adherence to permission warnings fell over three weeks, while warnings whose appearance varied (polymorphic designs) substantially reduced this habituation.
SupportsQualitative · 2014
Kirlappos et al. — Workshop on Usable Security (USEC 2014)
Beyond comply/not-comply, security-conscious employees who cannot follow policy build their own workarounds ('shadow security') that balance getting work done with managing risk. The authors recommend learning from these practices rather than stamping them out.